Back to skill

Security audit

Aha Orch Xx

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only orchestration skill that tells an agent how to choose and disclose collaboration tools; it does not install code or request hidden access.

Install this if you want your agent to use structured delegation and verification. Be aware it may encourage use of available subagents, worktrees, or handoff files for non-trivial tasks, but the artifacts require those choices to stay bounded, disclosed, and gated when they raise cost, risk, or permissions.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The file explicitly mandates operator-facing orchestration disclosures be kept to very low verbosity, capped at three sentences and one-line progress updates. In a security- and permission-sensitive orchestration framework, this can suppress material context about risk, confirmation triggers, capability choices, and deviations, increasing the chance that users approve or miss sensitive actions without adequate understanding.

Static analysis

No suspicious patterns detected.